Security Concern - TapaTalk

Is this the low risk vulnerability patched a month ago?

Oh, I guess it was.
I am assuming so.... I was a little short on a post with them there about their roll it into existing code and not notifying the tapatalk associated forum owners (heck they already send you email blasts about other crud). Got a response pretty quickly back from Winter advising the typical mumbo-jumbo but stating that they would be notifying the forum owners via email.
 
They locked the thread about this on the Tapatalk forum. That's fairly disrespectful to forum owners, in my opinion, particularly since no announcement has been made yet.

"We have this admitted vulnerability. We silently patched against it by updating the addon, but since we didn't want to own the issue or get any publicity for it, we didn't bother to let anyone know that we updated the published files."

The word irresponsible comes to mind.
 
After that, I removed Tapatalk from my site. I told members it was due to security issues and advertising and although a few were unhappy, most understood. I've not looked back since and members can now see and use the various extras like Xenforo Media Gallery as well as basic functions such as font sizes and colours that Tapatalk couldn't support.

So for me, I'll never go back to Tapatalk.

Well I was lucky in this as well once the members heard of the security risk to the forum they agreed it must be removed. They were disappointed though but understood

Is this the low risk vulnerability patched a month ago?

Oh, I guess it was.

Yeah so low risk that it compromised my server

Cross-Site Scripting vulnerabilities are often used against specific users of a website to steal their credentials or to conduct spoofing attacks.

Source - http://www.securelist.com/en/advisories/58348

My phone was infected and they got some of my private information :mad:
 
I don't like Tapatalk and the increasing number of vulnerabilities is worrying, I'd just prefer to kill it off rather than run the risk of introducing security issues.
 
When I'm browsing on a smartphone I always try and avoid those things like tapatalk and mobile skins. These days I find they are just not necessary and I'd rather browse sites normally even if it involves plenty of pinching and scrolling, the experience is always better
 
Last edited:
Not telling anyone is part of their plan for your forums safety according to the email :ROFLMAO:

We will only be communicating this issue via email to avoid broadcasting the existence of the vulnerability and putting forum owners who have not yet updated in unnecessary risk.
 
My Members can't be without it... :(
T3.webp

tapatalk.webp

Tapatalk2.webp
 
tapatalk.webp

Tapatalk is just BS. I uninstalled tapatalk on May 2nd, so how the hell am I getting users and ad impressions when it is not even installed on my site?? :eek: And if I was running Tapatalk, at no point would I EVER consider their numbers correct. I am still generating ad impressions on a system that is not even installed.:ROFLMAO:

Best thing I did was remove it. I found out here that there is the security issue. I still have not received a email about it. They are just criminals at this point.

Russ
 
Top Bottom